2000Unpublished venueRequires access

Authentication and Key Agreement via Memorable Password.

Taekyoung Kwon

Open publisher page 18 citations

Abstract

This paper presents a new password authentication and key agreement protocol, AMP, based on the ampli ed password idea. The intrinsic problems with password authentication are the password itself has low entropy and the password le is very hard to protect. We presentthe ampli ed password proof and the ampli ed password le for solving these problems. A party commits the high entropy information and ampli es her password with that information in the amplifed password proof. She never shows any information except that she knows it. Our ampli ed password proof idea is very similar to the zero-knowledge proof in that sense. We adds one more idea � the ampli ed password le for password le protection. Aserver stores the ampli ed veri ers in the ampli ed password le that is secure against a server le compromise and a dictionary attack. AMP mainly provides the password-veri er based authentication and the Di e-Hellman based key agreement, securely and e ciently. AMP is easy to generalize in any other cyclic groups. In spite of those plentiful properties, AMP is actually the most e cient protocol among the related protocols due to the simultaneous multiple exponentiation method. Several variants such as AMPi,AMPn,AMPn+, AMP +,AMP++, and AMPc are also proposed. Among them, AMPn is actually the basic protocol of this paper that describes the ampli ed password proof idea while AMP is the most complete protocol that adds the ampli ed password le. AMPi simply removes the ampli ed password le from AMP.Intheend,wegive a comparison to the related protocols in terms of e ciency. This manuscript is a preliminary version of our paper available from the IACR eprint archive,

About this research paper

What this paper is about

This paper presents a new password authentication and key agreement protocol, AMP, based on the ampli ed password idea. The intrinsic problems with password authentication are the password itself has low entropy and the password le is very hard to protect. We presentthe ampli ed password proof and the ampli ed password le for solving these problems. A party commits the high entropy information and ampli es her password with that information in the amplifed password proof. She never shows any information except that she knows it. Our ampli ed password proof idea is very similar to the zero-knowledge proof in that sense. We adds one more idea � the ampli ed password le for password le protection. Aserver stores the ampli ed veri ers in the ampli ed password le that is secure against a server le compromise and a dictionary attack. AMP mainly provides the password-veri er based authentication and the Di e-Hellman based key agreement, securely and e ciently. AMP is easy to generalize in any other cyclic groups. In spite of those plentiful properties, AMP is actually the most e cient protocol among the related protocols due to the simultaneous multiple exponentiation method. Several variants such as AMPi,AMPn,AMPn+, AMP +,AMP++, and AMPc are also proposed. Among them, AMPn is actually the basic protocol of this paper that describes the ampli ed password proof idea while AMP is the most complete protocol that adds the ampli ed password le. AMPi simply removes the ampli ed password le from AMP.Intheend,wegive a comparison to the related protocols in terms of e ciency. This manuscript is a preliminary version of our paper available from the IACR eprint archive,

Why it matters

OpenAlex reports 18 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

This paper presents a new password authentication and key agreement protocol, AMP, based on the ampli ed password idea. The intrinsic problems with password authentication are the password itself has low entropy and the password le is very hard to protect. We presentthe ampli ed password proof and the ampli ed password le for solving these problems. A party commits the high entropy information and ampli es her password with that information in the amplifed password proof. She never shows any information except that she knows it. Our ampli ed password proof idea is very similar to the zero-knowledge proof in that sense. We adds one more idea � the ampli ed password le for password le protection. Aserver stores the ampli ed veri ers in the ampli ed password le that is secure against a server le compromise and a dictionary attack. AMP mainly provides the password-veri er based authentication and the Di e-Hellman based key agreement, securely and e ciently. AMP is easy to generalize in any other cyclic groups. In spite of those plentiful properties, AMP is actually the most e cient protocol among the related protocols due to the simultaneous multiple exponentiation method. Several variants such as AMPi,AMPn,AMPn+, AMP +,AMP++, and AMPc are also proposed. Among them, AMPn is actually the basic protocol of this paper that describes the ampli ed password proof idea while AMP is the most complete protocol that adds the ampli ed password le. AMPi simply removes the ampli ed password le from AMP.Intheend,wegive a comparison to the related protocols in terms of e ciency. This manuscript is a preliminary version of our paper available from the IACR eprint archive,

Key concepts: Password, S/KEY, Password strength, Zero-knowledge password proof, Computer science, One-time password, Computer security, Salt (chemistry)

Related papers

Back to paper searchBrowse research topicsOriginal source
Authentication and Key Agreement via Memorable Password. — Research Paper | ScholarLens